hijack this log pls help |
![]() ![]() |
hijack this log pls help |
Mar 30 2006, 03:08 PM
Post
#1
|
|
|
Member ![]() ![]() Posts: 20 OS: windows xp |
StartupList version: 1.52.2 Started from : C:\unzipped\hjt[1]\HijackThis.EXE Detected: Windows XP SP2 (WinNT 5.01.2600) Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180) * Using default options ================================================== Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\WINDOWS\System32\CTsvcCDA.exe C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\tcpsvcs.exe C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\MessengerPlus! 3\MsgPlus.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe C:\Program Files\Logitech\MouseWare\system\em_exec.exe C:\Program Files\OptusNet DSL Internet\DSC.exe C:\WINDOWS\CTHELPER.EXE C:\WINDOWS\system32\bcmwltry.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\PROGRA~1\INCRED~1\bin\IMApp.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Messenger\msmsgs.exe C:\unzipped\hjt[1]\HijackThis.exe -------------------------------------------------- Checking Windows NT UserInit: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] UserInit = C:\WINDOWS\system32\userinit.exe, -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup nwiz = nwiz.exe /install MessengerPlus3 = "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" zBrowser Launcher = C:\Program Files\Logitech\iTouch\iTouch.exe Logitech Utility = Logi_MwX.Exe CTSysVol = C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r Desktop Service Centre = C:\Program Files\OptusNet DSL Internet\DSC.exe CTHelper = CTHELPER.EXE bcmwltry = bcmwltry.exe ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" Symantec NetDriver Monitor = C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run IncrediMail = C:\Program Files\IncrediMail\bin\IncMail.exe /c MessengerPlus3 = "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart msnmsgr = "C:\Program Files\MSN Messenger\msnmsgr.exe" /background -------------------------------------------------- Shell & screensaver key from C:\WINDOWS\SYSTEM.INI: Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found* Shell & screensaver key from Registry: Shell=Explorer.exe SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr drivers=*Registry value not found* Policies Shell key: HKCU\..\Policies: Shell=*Registry value not found* HKLM\..\Policies: Shell=*Registry value not found* -------------------------------------------------- Enumerating Browser Helper Objects: NAV Helper - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872} -------------------------------------------------- Enumerating Task Scheduler jobs: Norton AntiVirus - Scan my computer - Ben.job Norton SystemWorks One Button Checkup.job Symantec Drmc.job -------------------------------------------------- Enumerating Download Program Files: [SupportSoft SmartIssue] InProcServer32 = C:\WINDOWS\Downloaded Program Files\tgctlsi.dll CODEBASE = http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab [SupportSoft Script Runner Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\tgctlsr.dll CODEBASE = http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab [Creative Software AutoUpdate] InProcServer32 = C:\WINDOWS\DOWNLO~1\CTSUEng.ocx CODEBASE = http://www.creative.com/su/ocx/15015/CTSUEng.cab [asusTek_sysctrl Class] InProcServer32 = C:\WINDOWS\DOWNLO~1\ASUSTE~1.DLL CODEBASE = http://support.asus.com/common/asusTek_sys_ctrl.cab [Symantec AntiVirus scanner] InProcServer32 = C:\WINDOWS\Downloaded Program Files\avsniff.dll CODEBASE = http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab [Driver_Detective_v43_Members.DD_v43] InProcServer32 = C:\WINDOWS\Downloaded Program Files\Driver_Detective_v43_Members.ocx CODEBASE = http://www.drivershq.com/files/cab/prod/Dr...v43_Members.CAB [Office Update Installation Engine] InProcServer32 = C:\WINDOWS\opuc.dll CODEBASE = http://office.microsoft.com/officeupdate/content/opuc3.cab [WUWebControl Class] InProcServer32 = C:\WINDOWS\System32\wuweb.dll CODEBASE = http://update.microsoft.com/windowsupdate/...b?1127051282421 [Symantec RuFSI Utility Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\rufsi.dll CODEBASE = http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab [MUWebControl Class] InProcServer32 = C:\WINDOWS\System32\muweb.dll CODEBASE = http://update.microsoft.com/microsoftupdat...b?1127051667984 [Housecall ActiveX 6.5] InProcServer32 = C:\WINDOWS\Downloaded Program Files\Housecall_ActiveX.dll CODEBASE = http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab [MessengerStatsClient Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\messengerstatsclient.dll CODEBASE = http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab [MsnMessengerSetupDownloadControl Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnMessengerSetupDownloader.ocx CODEBASE = http://messenger.msn.com/download/MsnMesse...pDownloader.cab [ActiveDataInfo Class] InProcServer32 = C:\PROGRA~1\COMMON~1\SYMANT~1\SymAData.dll CODEBASE = https://www-secure.symantec.com/techsupp/as...rl/SymAData.cab [Shockwave Flash Object] InProcServer32 = C:\WINDOWS\System32\Macromed\Flash\Flash8.ocx CODEBASE = http://download.macromedia.com/pub/shockwa...ash/swflash.cab [Creative Software AutoUpdate Support Package] InProcServer32 = C:\WINDOWS\DOWNLO~1\CTPID.ocx CODEBASE = http://www.creative.com/su/ocx/15021/CTPID.cab -------------------------------------------------- Enumerating Winsock LSP files: NameSpace #4: C:\WINDOWS\system32\pnrpnsp.dll NameSpace #5: C:\WINDOWS\system32\pnrpnsp.dll -------------------------------------------------- Enumerating Windows NT logon/logoff scripts: *No scripts set to run* Windows NT checkdisk command: BootExecute = autocheck autochk * Windows NT 'Wininit.ini': PendingFileRenameOperations: C:\DOCUME~1\Ben\LOCALS~1\Temp\~nsu.tmp\Au_.exe||C:\Program Files\ewido anti-malware\shellhook.dll|||? -------------------------------------------------- Enumerating ShellServiceObjectDelayLoad items: PostBootReminder: C:\WINDOWS\system32\SHELL32.dll CDBurn: C:\WINDOWS\system32\SHELL32.dll WebCheck: C:\WINDOWS\System32\webcheck.dll SysTray: C:\WINDOWS\System32\stobject.dll UPnPMonitor: C:\WINDOWS\system32\upnpui.dll -------------------------------------------------- End of report, 8,592 bytes Report generated in 0.016 seconds |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
5 / 190 | 6th December 2004 - 05:23 PM nerosrevenge started - last by -=jonnyrotten=- |
|||||
![]() |
0 / 79 | 5th September 2008 - 03:25 AM malkee started - last by malkee |
|||||
![]() |
11 / 294 | 16th December 2008 - 05:37 AM justjosh1822 started - last by heir |
|||||
![]() |
0 / 23 | 2nd January 2009 - 05:11 AM lawmansd started - last by lawmansd |
|||||
|
Time is now: 8th January 2009 - 02:58 AM |
| Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. |